Назад
Company hidden
4 дня назад

Third Party Risk Management (TPRM) Analyst (Cybersecurity)

85 000 - 120 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Third Party Risk Management (TPRM) Analyst (Cybersecurity): Managing and maturing the TPRM program to identify and mitigate security risks from third-party vendors with an accent on risk assessments, due diligence, and GRC process optimization. Focus on evaluating vendor controls across data security and compliance domains, managing remediation plans, and scaling the program through automation.

Location: Remote (Must be based in the USA)

Salary: $85,000–$120,000

Company

Global leader in cybersecurity providing an AI-native platform to stop breaches and protect modern organizations.

What you will do

  • Develop and maintain TPRM policies, standards, and assessment methodologies.
  • Conduct security risk assessments of third-party vendors across the full vendor lifecycle.
  • Tier and prioritize vendors based on risk factors, data sensitivity, and operational dependency.
  • Manage vendor risk findings and remediation plans, collaborating with vendors and internal stakeholders.
  • Create detailed reports and dashboards to track vendor risk posture and program KPIs.
  • Identify opportunities to automate and optimize TPRM workflows leveraging GRC tooling.

Requirements

  • Bachelor's degree in Computer Science, Information Security, Business, or related field, or up to 5 years of experience.
  • Technical focus on third party risk management, vendor risk, or supply chain security.
  • Experience with GRC or TPRM platforms such as ServiceNow, OneTrust, or ProcessUnity.
  • Strong understanding of control frameworks like SOC 1/2, ISO 27001/27002, NIST 800-53, GDPR, and PCI-DSS.
  • Experience reviewing vendor security documentation, including SOC reports and penetration test results.
  • Must be based in the USA.

Nice to have

  • Certifications such as CISSP, CISM, CRISC, or CTPRP.
  • Experience with continuous monitoring solutions like BitSight or SecurityScorecard.
  • Familiarity with hirify.global products or practical experience in secure coding and SBOM.

Culture & Benefits

  • Market-leading compensation and equity awards.
  • Comprehensive physical and mental wellness programs.
  • Competitive vacation, holidays, and paid parental/adoption leave.
  • Professional development opportunities for all employees regardless of level.
  • Vibrant office culture and diverse employee networks.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →